Menu

#25 CAN-2005-2965: flexbackup <= 1.2.1 multiple vulnerabilities

open
nobody
None
5
2008-08-24
2008-08-24
No

See the following Gentoo Linux Bugzilla bugs for full details:
http://bugs.gentoo.org/show_bug.cgi?id=105000
http://bugs.gentoo.org/show_bug.cgi?id=116510

Summary: Possible symlink attack (race condition), and also possibility to create a untrusted script into the tmp_script (race condition).

Discussion

  • John R. Graham

    John R. Graham - 2008-08-24

    Logged In: YES
    user_id=1745635
    Originator: YES

    Patch #1 of 2. Addresses race condition but introduced some remote buffer test issues.

     
  • John R. Graham

    John R. Graham - 2008-08-24

    Logged In: YES
    user_id=1745635
    Originator: YES

    Hmm. Can't attach the patch file. SourceForge issue? Will try later.

     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.